Skip to content

Threat Profile: Qilin (Agenda) Ransomware Syndicate & DFIR Master Investigation Guide

HTS

HERMES THREAT SCORE & OPERATIONAL EXPLOITABILITY

Target: Healthcare Systems, Critical Infrastructure, Active Directory & VMware ESXi Hypervisors
Confidence: 99%
96 / 100
EXTREME

Measures real-world operational relevance, exploit weaponization, and active threat posture.

Dimension Breakdown
Exploitability 20 / 20
Threat Activity 20 / 20
Weaponization 15 / 20
Exposure 15 / 20
Prevalence 15 / 20
Impact 11 / 20
โš–๏ธ Divergence & Operational Rationale

Rated 96 EXTREME by Hermes due to devastating high-consequence targeting (e.g., Synnovis / NHS London pathology attack), advanced anti-analysis execution password gating, kernel-level BYOVD driver evasion (ProcPrv.sys), unique Active Directory GPO Chrome credential theft, and ultra-fast Rust-based multi-platform encryption.


Qilinโ€™s operational trajectory illustrates the rapid evolution of modern enterprise ransomware:

  • August 2022 (Agenda Era): The group first surfaced under the name โ€œAgenda,โ€ developing modular ransomware payloads in Go (Golang). Early campaigns targeted healthcare and education targets in Southeast Asia and South Africa.
  • September โ€“ October 2022 (Qilin Rebranding): The syndicate rebranded as โ€œQilinโ€ (referencing the mythical chimerical beast from Asian mythology) and launched an aggressive recruitment drive on top-tier Russian-language underground cybercrime forums (RAMP, Exploit, XSS).
  • 2023 โ€“ 2024 (The Rust Rewrite - Qilin.B): Following the operational footsteps of BlackCat/ALPHV, Qilin completely rewrote its ransomware core from Go into Rust. This transition yielded massive offensive advantages:
    • Memory Safety & Multi-Threading: Rust enables blazing-fast parallelized file traversal without memory leaks or race conditions.
    • Compiler Obfuscation: Rust-compiled binaries produce highly convoluted control flow graphs and deeply nested data structures, rendering legacy antivirus signatures and commercial decompiler heuristics (IDA Pro, Ghidra) largely ineffective.
  • Mid-2024 โ€“ Present (The Multi-Extortion Giant): Qilin emerged as a dominant ransomware group worldwide, specializing in catastrophic disruptions of critical healthcare providers, automotive supply chains (Yanfeng), and manufacturing giants.
Qilin (Agenda) Syndicate Evolution & Architecture:
โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚ August 2022: Emergence as "Agenda" โ”‚
โ”‚ - Authored in Go (Golang) โ”‚
โ”‚ - Basic AES-256 + RSA implementations โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
โ”‚
โ–ผ
โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚ Mid-2023 - Present: Rebranding to "Qilin" (Qilin.B) โ”‚
โ”‚ โ”œโ”€โ”€ Complete Payload Architecture Rewrite in Rust โ”‚
โ”‚ โ”œโ”€โ”€ Linux / VMware ESXi 64-bit ELF Specialization โ”‚
โ”‚ โ”œโ”€โ”€ Anti-Sandbox Command-Line Password Protection โ”‚
โ”‚ โ”œโ”€โ”€ Kernel BYOVD Defense Evasion (ProcPrv.sys) โ”‚
โ”‚ โ””โ”€โ”€ Novel AD GPO-Driven Chrome Password Harvester โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
โ”‚
โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ–ผ โ–ผ
โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ” โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚ Tor Negotiation Portal โ”‚ โ”‚ Multi-Extortion Data Leak Site โ”‚
โ”‚ - Unique Victim Company Chat โ”‚ โ”‚ - Public Shaming & Data Auctions โ”‚
โ”‚ - Monero & Bitcoin Escrow โ”‚ โ”‚ - Multi-Terabyte File Disclosures โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜ โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

Qilin operates an affiliate-driven platform with an aggressive profit-sharing structure, offering affiliates up to 80% to 85% of paid ransoms. Ransoms typically range from $500,000 to over $50,000,000 USD.

The syndicate practices triple extortion:

  1. Confidentiality Breach (Double Extortion): Stealing multi-terabyte volumes of proprietary, financial, and patient data prior to encryption, threatening public auction on their Tor leak portal.
  2. Availability Destruction (Primary Extortion): Encrypting Windows file shares, SQL databases, and VMware ESXi datastores with uncrackable hybrid cryptography.
  3. Operational Harassment (Triple Extortion): Launching Distributed Denial of Service (DDoS) attacks against the victimโ€™s public portals and directly telephoning or emailing board members, partners, and media outlets to amplify pressure.

2. The Synnovis / NHS London Healthcare Intrusion (Case Study)

Section titled โ€œ2. The Synnovis / NHS London Healthcare Intrusion (Case Study)โ€

The June 2024 attack on Synnovis remains one of the most consequential healthcare ransomware events in history, providing critical threat telemetry on Qilinโ€™s real-world operational methodology:

Synnovis / NHS London Attack Lifecycle (June 2024):
[Initial Ingress] โ”€โ”€โ–บ Compromise of unpatched perimeter VPN portal lacking MFA
โ”‚
[Domain Domination] โ”€โ”€โ–บ Rapid privilege escalation via Kerberoasting; dumping LSASS on DC
โ”‚
[GPO Password Steal] โ”€โ”€โ–บ Deploy malicious GPO to harvest all employee Chrome passwords to SYSVOL
โ”‚
[Data Exfiltration] โ”€โ”€โ–บ Exfiltrate 400 GB of confidential patient diagnostic data to cloud storage
โ”‚
[Virtualization Wipe] โ”€โ”€โ–บ Kill running pathology VMs; deploy Rust ELF encryptor across ESXi clusters
โ”‚
[Massive Disruption] โ”€โ”€โ–บ 1,700+ surgeries canceled; emergency blood donor appeals; $50M ransom demand
  • Target: Synnovis, a specialized pathology partnership between international diagnostic provider SYNLAB and two major London NHS hospital trusts: Guyโ€™s and St Thomasโ€™ NHS Foundation Trust and Kingโ€™s College Hospital NHS Foundation Trust.
  • Intrusion Vector: Threat actors gained access via an external VPN portal that lacked multi-factor authentication (MFA), followed by rapid lateral movement to core Active Directory Domain Controllers.
  • Healthcare Paralyzation:
    • The ransomware knocked offline Synnovisโ€™s laboratory information management systems (LIMS), completely halting blood transfusion matching, emergency blood testing, and pathology analysis across six major London hospitals and hundreds of primary care clinics.
    • 1,700+ planned surgical procedures and cancer operations were abruptly postponed.
    • 10,000+ outpatient appointments were canceled or rescheduled.
    • NHS Blood and Transplant issued an urgent public appeal for O-positive and O-negative blood donors due to the inability to safely verify matched blood types.
  • Extortion Outcome: Qilin demanded a $50 million USD ransom. When the UK Government and NHS refused payment, Qilin published nearly 400 gigabytes of sensitive patient medical data on their darknet leak site, exposing full names, dates of birth, NHS numbers, and pathology test descriptions.

  • Perimeter Gateway Exploitation: Qilin actors heavily target internet-facing edge infrastructure, prominently weaponizing Citrix NetScaler ADC vulnerabilities (such as CVE-2023-4966 Citrix Bleed for unauthenticated session hijacking and CVE-2023-3519 for remote code execution).
  • Fortinet FortiOS Exploitation: Actively scanning and exploiting Fortinet SSL-VPN endpoints (CVE-2026-22708 and CVE-2024-21762).
  • Single-Factor Credential Stuffing & RDP: Compromising external VPN and Remote Desktop Protocol (RDP) servers lacking multi-factor authentication using credentials purchased from Initial Access Brokers (IABs).
  • Spear-Phishing: Deploying targeted emails containing ISO images, password-protected ZIP archives, or malicious PDF documents masquerading as executive job offers or legal notices.

Active Directory GPO-Driven Chrome Credential Theft (Signature TTP)

Section titled โ€œActive Directory GPO-Driven Chrome Credential Theft (Signature TTP)โ€

In July 2024, Sophos X-Ops researchers discovered an unprecedented operational capability in Qilinโ€™s arsenal: weaponizing Active Directory Group Policy Objects to execute domain-wide automated theft of Google Chrome credentials:

Qilin AD GPO Chrome Credential Stealing Sequence:
1. Threat Actor gains Domain Admin on Primary DC.
2. Modifies Default Domain Policy:
โ”œโ”€โ”€ Injects logon batch file: \\<DOMAIN>\SYSVOL\<domain>\Policies\...\logon.bat
โ””โ”€โ”€ Injects PowerShell payload: \\<DOMAIN>\SYSVOL\<domain>\Policies\...\IPScanner.ps1
3. Workstation User logs into Windows endpoint:
โ””โ”€โ”€ Group Policy triggers logon.bat in user context.
4. IPScanner.ps1 executes:
โ”œโ”€โ”€ Copies: %LOCALAPPDATA%\Google\Chrome\User Data\Default\Login Data (SQLite)
โ”œโ”€โ”€ Extracts DPAPI Master Key from: %LOCALAPPDATA%\Google\Chrome\User Data\Local State
โ”œโ”€โ”€ Decrypts AES-256-GCM browser passwords in memory
โ””โ”€โ”€ Exfiltrates: Writes credentials back to SYSVOL (\\<DOMAIN>\SYSVOL\temp.log & LD_<HOSTNAME>)
5. Threat Actor harvests thousands of corporate & personal passwords from single SYSVOL share!

This tactic provides Qilin with immense strategic leverage:

  • Stealth: Traffic never leaves the local network during the harvesting phase; the collection occurs entirely within the trusted Windows SYSVOL domain share.
  • Persistence Multiplier: Even if the initial ransomware intrusion is contained, the threat actors retain plain-text credentials for all employee cloud accounts, personal banking portals, SaaS tools, and remote access systems.

Defense Evasion via Bring Your Own Vulnerable Driver (BYOVD) (TA0005)

Section titled โ€œDefense Evasion via Bring Your Own Vulnerable Driver (BYOVD) (TA0005)โ€

To neutralize Endpoint Detection and Response (EDR) sensors, Qilin relies on kernel-level BYOVD attacks:

  1. Dropping Signed Vulnerable Drivers: The group drops legitimately signed third-party drivers, most notably ProcPrv.sys (associated with the Process Prowler administrative utility), zam.sys (Zemana), or mhyprot2.sys.
  2. Service Registration:
    Terminal window
    sc create ProcPrvService type= kernel binPath= C:\Windows\Temp\ProcPrv.sys
    net start ProcPrvService
  3. Ring 0 Process Termination: The companion user-mode malware communicates with the driver via Device I/O Control (DeviceIoControl) to execute arbitrary kernel memory writes. The driver strips process protection flags (PS_PROTECTED_PROCESS) from EDR processes and forcibly terminates them from kernel space, completely blinding defenses.
  4. Disabling Windows Defender via Registry:
    Terminal window
    reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender" /v DisableAntiSpyware /t REG_DWORD /d 1 /f
    reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection" /v DisableRealtimeMonitoring /t REG_DWORD /d 1 /f
    reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection" /v DisableBehaviorMonitoring /t REG_DWORD /d 1 /f

Discovery, Credential Access & Lateral Movement (TA0007, TA0006 & TA0008)

Section titled โ€œDiscovery, Credential Access & Lateral Movement (TA0007, TA0006 & TA0008)โ€
  • Reconnaissance Tooling: Executing SharpHound.exe or BloodHound.py for Active Directory attack path mapping, alongside AdFind.exe and netscan.exe.
  • LSASS Dumping: Extracting credentials from memory using Mimikatz (sekurlsa::logonpasswords), ProcDump, or native API minidumps via comsvcs.dll.
  • Kerberoasting & AS-REP Roasting: Utilizing Rubeus.exe to harvest service tickets for offline password cracking.
  • Lateral Traversal: Moving laterally across the enterprise via PsExec, WMI (wmic process call create), and Remote Desktop Protocol (RDP) sessions.

Collection & Double-Extortion Exfiltration (TA0009 & TA0010)

Section titled โ€œCollection & Double-Extortion Exfiltration (TA0009 & TA0010)โ€
  • Data Staging: Archiving sensitive directories with 7-Zip or WinRAR using custom shell scripts:
    Terminal window
    7z.exe a -p"QilinPass2026!" -m0=lzma2 -mx=1 C:\Windows\Temp\stage_data.7z "D:\SensitiveShares\*"
  • Exfiltration Pipelines: Exfiltrating staged archives to private cloud infrastructure via Rclone, MegaSync, and custom Python multi-threaded uploaders routing to Mega.nz, Wasabi, and dedicated Russian-hosted SFTP servers.

The modern Qilin encryptor (Qilin.B) is built with Rust, producing multi-threaded binaries tailored for both Windows PE64 and Linux/ESXi ELF64 architectures.

Qilin Encryptor Execution & Anti-Analysis Verification:
Binary Launch:
qilin.exe --password <SECRET_HEX_KEY> --mode fast --path C:\
โ”‚
โ–ผ
Anti-Analysis Password Check:
โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚ Is --password argument provided? โ”‚
โ”‚ โ”œโ”€โ”€ NO โ”€โ”€โ–บ Terminate immediately (Defeats auto-sandboxes) โ”‚
โ”‚ โ””โ”€โ”€ YES โ”€โ”€โ–บ Decrypt internal configuration & public keys โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
โ”‚
โ–ผ
Multi-Threaded Work Queue (Rayon / Tokio):
โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚ Check File Size & Selected Mode: โ”‚
โ”‚ โ”œโ”€โ”€ fast โ”€โ”€โ–บ Encrypt first N MB + append RSA wrapped key โ”‚
โ”‚ โ”œโ”€โ”€ step โ”€โ”€โ–บ Skip intervening blocks (50% ratio) โ”‚
โ”‚ โ””โ”€โ”€ full โ”€โ”€โ–บ Encrypt 100% of bytes with AES-256 / ChaCha20 โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
โ”‚
โ–ผ
Append Encrypted Footer & Rename:
<filename>.<victim_id_ext> & Drop: README-RECOVER-[ID].txt

A signature hallmark of Qilin is its mandatory execution password. The ransomware binary cannot execute without a specific command-line argument supplied by the affiliate:

Terminal window
qilin.exe --password "e7a8f9b0c1d2e3f4a5b6c7d8e9f0a1b2"
  • If the binary is launched inside an automated sandbox or run by a malware analyst without the key, it immediately exits with zero activity.
  • The password string serves as the cryptographic decryption key to unpack the malwareโ€™s embedded JSON configuration (which contains the list of processes to kill, services to stop, target directories, and the threat actorโ€™s RSA public key).
  • Symmetric Encryption (AES-256-CTR / ChaCha20-Poly1305): In Rust builds, Qilin utilizes either AES-256 in CTR/GCM mode or ChaCha20-Poly1305. Each file receives an ephemeral 256-bit symmetric key and initialization vector generated via cryptographically secure random number generators.
  • Asymmetric Key Wrapping (RSA-4096 / ECC Curve25519): The per-file symmetric key is encrypted using an embedded RSA-4096 or ECC public key and appended to the file footer.
  • Configurable Encryption Modes:
    • --mode fast: Encrypts only the first few megabytes (or header and footer), maximizing speed while corrupting file integrity.
    • --mode step: Encrypts blocks of data at regular intervals (e.g., encrypt 1 MB, skip 1 MB).
    • --mode full: Encrypts the entire file from byte 0 to EOF.

The Linux variant is an ELF64 binary compiled with Rust. When deployed to VMware ESXi hypervisors:

  1. Virtual Machine Discovery: Lists all running and registered virtual machines:
    Terminal window
    vim-cmd vmsvc/getallvms | awk '{print $1}'
  2. Forced VM Termination: Kills VM processes to release disk locks:
    Terminal window
    esxcli vm process kill --type=force --world-id=<WORLD_ID>
    vim-cmd vmsvc/power.off <VM_ID>
  3. Datastore Traversal: Recursively navigates /vmfs/volumes/, targeting:
    • .vmdk (Virtual Machine Disks)
    • .vmem (Virtual Machine Memory)
    • .vmx (Virtual Machine Configuration)
  4. Command-Line Arguments (Linux / ESXi):
    Terminal window
    ./qilin_esx --password <PASSWORD> --path /vmfs/volumes/ --mode fast --clean

When managing an active Qilin ransomware intrusion, incident response teams must execute a structured, rapid-triage playbook:

  1. Immediate GPO Remediation & Domain Isolation:

    • Audit Active Directory SYSVOL: Immediately check \\<DOMAIN>\SYSVOL\<domain>\Policies\ for newly modified GPOs containing IPScanner.ps1 or logon.bat.
    • Disable Rogue GPOs: Immediately unlink or disable any unauthorized GPO logon scripts to prevent further workstation Chrome password theft.
    • Isolate Perimeter Ingress: Sever external access on Citrix NetScaler, Fortinet, and VPN gateways.
  2. Volatile RAM Acquisition (Critical Cryptographic Window):

    • Do NOT power off or reboot servers.
    • Dump volatile RAM using WinPmem, DumpIt, or hypervisor memory snapshots. RAM dumps can capture the command-line parameters (revealing the --password string required to unpack the binary) and volatile AES/ChaCha20 keys before memory is overwritten.
  3. Active Directory Enterprise Credential Revocation:

    • Because Qilin may have harvested all stored Chrome passwords from domain users via GPO, force an enterprise-wide reset of all user passwords, cloud SSO sessions, and VPN credentials.
    • Perform a double reset of the Active Directory KRBTGT account password to invalidate forged Golden/Silver Kerberos tickets.
  4. Forensic Hunting Across Endpoint Artifacts:

    • Check Windows Event ID 7045 and Sysmon Event 6 for the installation of vulnerable drivers (ProcPrv.sys, zam.sys).
    • Audit %LOCALAPPDATA%\Google\Chrome\User Data\Default\Login Data file access timestamps across endpoints to determine which machines were targeted for password dumping.
    • Inspect SRUM (SRUDB.dat) to determine data volumes exfiltrated by staging tools.
  5. VMware ESXi Hypervisor Log Triage:

    • Review /var/log/shell.log and /var/log/auth.log for unauthorized SSH connections.
    • Audit /var/log/vmkernel.log for forced VM termination events (esxcli vm process kill).
Artifact SourcePath / System LocationDFIR Investigation Significance
Active Directory GPO\\<DOMAIN>\SYSVOL\<domain>\Policies\<GUID>\Inspect for IPScanner.ps1, logon.bat, LD, and temp.log. Proves network-wide Chrome credential harvesting.
System Event LogEvent ID 7045Proves installation of kernel services for BYOVD attacks (ProcPrv.sys, zam.sys).
Sysmon Event LogEvent ID 6 (Driver Loaded)Identifies unsigned or vulnerable drivers loaded into the Windows kernel to blind EDR agents.
Sysmon Event LogEvent ID 1 (Process Creation)Captures command-line arguments containing --password, --mode, and --path.
Browser Credentials%LOCALAPPDATA%\Google\Chrome\User Data\Default\Login DataSQLite database holding browser passwords; check Last Access Time to confirm compromise.
DPAPI State%LOCALAPPDATA%\Google\Chrome\User Data\Local StateContains encrypted AES master keys used by Chrome.
SRUM DatabaseC:\Windows\System32\sru\SRUDB.datQuantifies total network byte transfers by masqueraded exfiltration processes.
ESXi Shell Log/var/log/shell.logRecords commands executed in the ESXi shell (e.g., esxcli vm process kill, ./qilin_esx).

title: Qilin AD GPO Chrome Credential Harvesting Script Deployment
id: e4b2d198-7712-4fc9-b102-qilin001
status: stable
description: Detects the deployment or execution of Qilin's signature Active Directory GPO credential harvesting scripts (IPScanner.ps1, logon.bat) targeting Google Chrome Login Data.
author: Hermes Codex CTI
date: 2026-09-08
references:
- https://news.sophos.com/en-us/category/threat-research/
- https://hermes-codex.internal/threat-intel/qilin-ransomware/
tags:
- attack.credential_access
- attack.t1555.003
- attack.defense_evasion
- attack.t1484.001
logsource:
category: process_creation
product: windows
detection:
selection_script:
CommandLine|contains:
- 'IPScanner.ps1'
- 'Login Data'
- 'Local State'
selection_sysvol:
CommandLine|contains:
- '\SYSVOL\'
- '\Policies\'
selection_powershell:
Image|endswith:
- '\powershell.exe'
- '\pwsh.exe'
- '\cmd.exe'
condition: selection_powershell and (selection_script or (selection_sysvol and selection_script))
falsepositives:
- Legitimate administrative inventory scripts querying browser versions (verify script source in SYSVOL).
level: critical

Investigation DimensionCodex Dossier / ToolOperational Focus & DFIR Synergies
Incident Response PlaybookRansomware Investigation PlaybookEnd-to-end DFIR methodology covering immediate containment, RAM acquisition, and forensic host rebuilds.
Lateral Movement AnalysisLateral Movement: SMB vs RDPForensics on network pivot mechanics, Event 4624 Logon Type 10 vs Type 3, and PsExec tracking.
Credential ForensicsActive Directory Credential AttacksInvestigating LSASS memory dumps, Kerberoasting, and domain password extraction.
Peer Syndicate ComparisonAkira Ransomware Master DossierComparative analysis with Akira, detailing overlapping perimeter exploitation vectors and ESXi wiping routines.
Perimeter VulnerabilityCVE-2026-83548: SonicWall SMA1000 SSRFTechnical root cause of edge gateway zero-days heavily exploited by contemporary RaaS syndicates.
Threat Actor ProfileInitial Access Brokers (IAB)Understanding the illicit brokers supplying stolen Citrix, Fortinet, and VPN access tokens to Qilin affiliates.
Interactive Defense ToolAgentThreat StudioModel enterprise perimeter boundaries and untrusted ingress channels in threat simulation architectures.